tencent cloud

Tencent Cloud Organization

  • Product Introduction
  • Purchase Guide
  • Operation Guide
    • Console Overview
    • Organization Settings
    • Department Management
    • Member Account Management
    • Member Finance Management
    • Member Access Management
    • Resource Management
    • Member Audit
    • Identity Center Management
  • API Documentation
    • History
    • Introduction
    • API Category
    • Making API Requests
    • Organization Settings APIs
    • Department and Member Management APIs
    • ListOrganizationIdentity
    • Unified Member Login APIs
    • Organization Service Management APIs
    • Organization Management Policy APIs
    • Resource Sharing APIs
    • Identity Center Management APIs
    • Identity Center User Management APIs
    • Identity Center User Group Management APIs
    • Identity Center Management SCIM Synchronization APIs
    • Identity Center Single Sign-On Management APIs
    • Identity Center Permission Configuration Management APIs
    • Identity Center Multi-Account Authorization Management APIs
    • Identity Center Sub-User Synchronization Management APIs
    • Data Types
    • Error Codes
    • TCO API 2018-12-25
  • Related Agreement
  • FAQs
  • Glossary

Enabling Service Control Policy

PDF
Focus Mode
Font Size
Last updated: 2024-03-06 18:52:29
The service control policy feature is disabled by default. You need to enable it before using it.

Background

After the service control policy feature is enabled, your organization will have the following changes:
All departments and members in your organization are bound to the system policy FullQcloudAccess by default, which allows them to perform any operations on all your Tencent Cloud resources.
When a department or member is created, it will be automatically bound to the system policy FullQcloudAccess.
After a Tencent Cloud account accepts the invitation to join your organization, it will be automatically bound to the system policy FullQcloudAccess.
When a member is removed, all service control policies bound to it will be unbound automatically.

Directions

1. Log in to the TCO console.
2. On the left sidebar, select Organization account > Service control policy.
3. Toggle on Service control policy.

Subsequent steps

You can create a custom service control policy (such as denying an operation on a resource) and bind it to a department or member in your organization. For detailed directions, see the following documents:

Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback